The PCI Security Standards Council (PCI SSC) has released new guidance, "Security Considerations for AI Systems," aimed at securing artificial intelligence deployments within payment environments and defending against AI-assisted attacks. The advisory document, developed in collaboration with industry stakeholders, covers governance, deployment, access controls, testing, and the application of existing PCI standards, which take precedence over the new recommendations.
A core recommendation emphasizes a "least agency" approach, limiting AI systems to only the access and capabilities necessary for their assigned tasks. Organizations are advised to define an AI system's purpose, permissions, and data access before deployment. A designated human individual should formally accept responsibility for AI output, and specific actions requiring human approval must be clearly defined. For AI agents with access to cleartext cardholder data, explicit human approval is recommended for any actions involving that data.
The guidance also addresses the management of sensitive data and credentials. AI systems should not handle, generate, or manage unprotected high-impact secrets such as passwords or cryptographic keys. Instead, credentials should be managed via secrets-management tools and kept out of source code, prompts, AI context, outputs, and logs. When random values are needed, a trusted random-number generator should be used, with values for passwords or cryptographic keys potentially needing to remain entirely outside the AI system. The PCI SSC recommends using encrypted or tokenized payment data whenever possible, with independent data-loss prevention controls. Logs should support investigations without retaining sensitive payment information.
Organizations are urged to maintain an AI inventory and bill of materials, detailing models, versions, hosting, integrations, data-use and retention policies, and intended users. An acceptable-use policy and technical controls are also recommended to identify and restrict "shadow AI"—unapproved tools used by employees. Access restrictions should be enforced through independent controls like identity-management policies and network isolation. The guidance advises against combining sensitive data access, external communications, and unrestricted input from untrusted sources within a single AI system. If a workflow requires all three, responsibilities should be separated among agents with different permissions.
Testing safeguards before extensive functional or user-acceptance testing is crucial, including adversarial testing to check for bypasses. Continuous monitoring and revalidation throughout deployment are necessary to detect behavioral changes. Review processes should also account for potential "excessive trust" in AI output, which could lead reviewers to overlook mistakes. For monitored autonomous AI, organizations should define permitted actions, approval requirements, shutdown triggers, and procedures for reversing changes, with a human remaining ultimately responsible.
The PCI SSC warns that AI can accelerate vulnerability discovery, exploit development, and social engineering. Recommended defenses include ongoing vulnerability monitoring, prioritizing findings and patches, limiting services and permissions, isolating legacy systems, using phishing-resistant authentication, encrypting sensitive data, and containing breach impacts. AI-generated code and patches should undergo security and functional testing, with reviews checking for embedded credentials, unsuitable dependencies, newly introduced weaknesses, and whether fixes address the underlying problem.
When engaging external AI providers with access to sensitive data, organizations should assess them under applicable third-party service provider requirements. Agreements should clarify responsibility for sensitive information, explicitly prohibit using the organization's data for AI training, provide visibility into subcontractors, and set breach notification terms. Incident response plans and periodic testing should cover prompt injection, model poisoning, actions outside approved scope, and unauthorized AI tools accessing sensitive data.
PCI DSS scoping for AI systems should consider deployment, isolation, access to account data (including data used for training), and the system's ability to affect the security of cardholder-data systems. Access to encrypted or tokenized data, combined with tools that can decrypt or detokenize it, should be treated as access to readable data.






